On 31 August 2026 11:51:45 BST, Greg Kroah-Hartman <[email protected]> wrote: >The ability to add and remove devices from a driver through the sysfs
Hello hello hello!! Right, this may not be a maintainer preference, but this patch is well needed, and well beneficial. Please bare I'm on a well deserved vacation, so I didn't review this super vigourisly. Reviewed-by: Bradley Morgan <[email protected]> >"bind" and "unbind" files was created all those decades ago as a way >that kernel developers can iterate faster, and provide a debugging way >for users to attempt to add a new device to a driver without having to >rebuild their kernel. > >This api over the years has been abused and recently come under a major >fuzzing "attack" through tools like syzbot which decided that it would >attempt to just randomly bind any driver to any type of device, causing >loads of unneeded errors and pointless kernel patches to be generated by >unsuspecting new developers. > >Handle all of this by adding a new taint flag, TAINT_FORCED_BIND, which >will be set on the driver if the bind/unbind sysfs files are ever >written to. This lets kernel developers "know" that a user is >attempting to do something that is not normal, and as such, if the >kernel breaks they get to keep the shiny pieces laying around on the >floor. > >The flag is 'Y' which was unused, and can remembered as the user is >"yeeting" the device being operated on here (thrown with force without >regard for the thing being thrown). > >Note, the taint flag gets set _BEFORE_ the bind/unbind callback happens, >as many times crashes/oops/warnings/failures happen within the callback, >and the taint flag needs to be there to show what was being attempted. >If it were to be set after the callback happens, the oops report would >not properly reflect what foolishness was being attempted. > >Fuzzing tools like syzbot, that doesn't have hand-crafted rules to keep >the tool from hitting bind/unbind, should be run with panic_on_taint >enabled so that they fall over and don't continue on, thinking that they >actually found a real issue. > >Userspace operations that rely on the bind/unbind files to work around >the lack of will to upgrade a kernel image to a newer version with >proper support for new devices, or the lack of will to submit valid >device ids to driver authors, will still work properly, but now the >kernel will be flagged in a way that will show that perhaps those users >should reconsider their behavior and work to have the drivers properly >support these devices in a "native" manner. > >Finally, the bind/unbind files can find real use-after-free issues with >some drivers by forcing the process to happen virtually without having >to rely on manual removal processes. Those real bugs should still be >worked on, but by adding this taint flag, developers can more easily >determine bug reports that are actually worth looking at. > >Signed-off-by: Greg Kroah-Hartman <[email protected]> >--- >Changes in v2: >- rebase on 7.3-rc1 >- Add changelog text to describe panic_on_taint and how it should be set > for tools like syzbot. >- Add changelog text to describe why 'Y' was picked. >- Fixes based on sashiko review: > - Make add_taint_module() handle a NULL for module pointer, fixing a > problem with built-in drivers. > - Fix up prototype for when CONFIG_MODULES is disabled so it will > actually build properly. > - rst table header fixes. >- Link to v1: >https://patch.msgid.link/[email protected] > >To: Luis Chamberlain <[email protected]> >To: Petr Pavlu <[email protected]> >To: Daniel Gomez <[email protected]> >To: Sami Tolvanen <[email protected]> >To: Aaron Tomlin <[email protected]> >To: Jonathan Corbet <[email protected]> >To: Shuah Khan <[email protected]> >To: Randy Dunlap <[email protected]> >To: Greg Kroah-Hartman <[email protected]> >To: "Rafael J. Wysocki" <[email protected]> >To: Danilo Krummrich <[email protected]> >To: Steven Rostedt <[email protected]> >To: Masami Hiramatsu <[email protected]> >To: Mathieu Desnoyers <[email protected]> >Cc: [email protected] >Cc: [email protected] >Cc: [email protected] >Cc: [email protected] >Cc: [email protected] > >--- >Greg Kroah-Hartman (2): > module: pull out add_taint_module() to be public > driver core: add TAINT_FORCED_BIND for when userspace manually messes > with devices and drivers > > Documentation/admin-guide/tainted-kernels.rst | 52 > ++++++++++++++------------- > drivers/base/bus.c | 3 ++ > include/linux/module.h | 10 ++++++ > include/linux/panic.h | 3 +- > include/trace/events/module.h | 3 +- > kernel/module/main.c | 16 +++++++-- > kernel/panic.c | 5 +-- > tools/debugging/kernel-chktaint | 8 +++++ > 8 files changed, 69 insertions(+), 31 deletions(-) >--- >base-commit: cee9395acd8043be0644b25c34bfa86623f2b935 >change-id: 20260825-bind_taint-d4077b870bc4 > >Best regards, >-- >Greg Kroah-Hartman <[email protected]> > --- Thanks! https://lore.kernel.org/all/[email protected]/
